• Dr.Web
  • Home

    E-licenses

    • Dr.Web Security Space
    • Anti-virus for Windows
    • Anti-virus for Mac OS X
    • Anti-virus for Linux
    • Mobile protection
    • OEM products

    Anti-virus as a service

    • Subscribe
    • Dr.Web Premium
    • Dr.Web Classic

    Services

    • Buy
    • Renew/Upgrade
    • Register
    • Update Dr.Web anti-virus to version 8.0
    • Demo
    • Dr.Web CureIt! free for home
    • License certificate
  • Business

    Products Dr.Web Enterprise Security Suite

    • Control center
    • Desktop protection
    • Server protection
    • E-mail protection
    • Gateway protection
    • Mobile protection
    • Licensing

    SMB bundles

    • Dr.Web Universal (5-50 PC)
    • Dr.Web for schools (10-200 PC)

    Curing utilities

    • Dr.Web CureNet!
    • Dr.Web CureIt!

    For banks

    • Dr.Web ATM Shield

    For IT service providers

    • Dr.Web AV-Desk

    For equipment manfactures

    • Dr.Web Mail Security Suite
    • Dr.Web Gateway Security Suite

    For ОEM suppliers

    • Dr.Web ОЕМ Universal
    • Dr.Web ОЕМ Mobile
    • Dr.Web ОЕМ Server

    Licenses&Certificates

    Services for users

    • Buy
    • Renew/Upgrade
    • Register
    • Online license certificate generation service
  • Download

    Ask for free trial

    • For home
    • For business
    • Protection of mobile devices
    • Dr.Web bundles
    • Curing utilities
    • Dr.Web LiveDemo for business

    Download

    • For home
    • For business

    Free services

    • Dr.Web for Android
    • Dr.Web Light for Mac

    System administrator emergency kit

    Curing utilities

    • Dr.Web CureNet!
    • Dr.Web CureIt!
    • Dr.Web LiveCD
    • Dr.Web LiveUSB

    LinkChecker

    • for IE
    • for Mozilla
    • for Opera
    • for Safari
    • for Google Chrome
    • Documentation
    • Localizations

    News

    • Dr.Web products
    • Sign up
    • RSS-feeds
  • eStore

    For new customers

    • eStore
    • Buy from partners

    Discounts

    • Migration for business
    • Edu and Health

    For returning customers

    • Renew licens
    • Upgrade license

    Dr.Web AV-Desk

    • Find a provider

    News

    • Promotions
    • Dr.Web products
    • Sign up
    • RSS-feeds
  • Support

    Services

    • Submit a request
    • Forums
    • Register
    • Online license certificate generation service

    Help on viruses

    • Online scanners
    • Send suspicious file
    • Report a malicious URL
    • Updates of Dr.Web virus database
    • Dr.Web virus database
    • Extended database

    News

    • Virus alerts
    • Virus reviews
    • Real-time threats news
    • Sign up
    • RSS-feeds

    Knowledge database

    • Update to v.8
    • FAQ
    • Wiki.drweb.com
    • Classification of viruses
    • Extended database
    • Types of viruses
    • Malicious programs
    • Unwanted programs
    • Glossary
    • Myths about Dr.Web

    Free

    • Free unblocking of Windows
    • Dr.Web CureNet! free
    • Dr.Web CureIt! free
    • Protect your mobile device free of charge!
  • Training

    For users

    • Courses
    • Register for exam

    For IT specialists and students

    • Courses and certification
    • Register for exam

    For partners and retailers

    • Courses and certification
    • Register for exam
    • External training cabinet

    News

    • Sign up
    • RSS-feeds
  • Partners

    Find partner

    • All partners
    • E-stores
    • Locate a distributor

    Partnership offerings

    • For distributors
    • For web site owners

    Partners area

    • Partner access
    • Restore password

    Training for partners

    • Courses and certification
    • Register for exam
  • EN
    • RU
    • FR
    • DE
    • JP


All news
Dr.Web products
Dr.Web AV-Desk
Dr.Web beta versions news
Updates of virus database
Virus alerts
Virus reviews
Real-time threats news
Promotions
Corporate news

Sign up

RSS-feeds


Information
Myths about Dr.Web
About viruses

Resources
Press center
For web-site owners

Buy
Buy from partners
Anti-virus As a Service
Buy online
License center
Contact sales

Cross-platform Trojan controls Windows and Mac machines

July 25, 2012

Russian anti-virus company Doctor Web is warning users about a dangerous cross-platform Trojan horse that provides criminals with full control over infected machines and can render a system non-operational. The malicious application, dubbed BackDoor.DaVinci.1, runs both in Windows and Mac OS X. Notably, the version for Mac OS X for the first time features rootkit technologies to hide the Trojan's processes and files.

BackDoor.DaVinci.1 is developed and sold by HackingTeam which has been in business since 2003. This malicious program is a multi-component backdoor that includes a large number of functional modules, such as drivers that use rootkit technologies, to hide the application in an operating system.

BackDoor.DaVinci.1 is spread as the AdobeFlashPlayer.jar file, signed using an invalid digital certificate. On July 23 a user sent this signed applet to Doctor Web for analysis.

screen

The file determines the OS type and saves and launches an infected application in the compromised system—currently, Doctor Web's virus analysts have Trojan samples intended for Windows and Mac OS X. It is known that a version targeting mobile platforms also exists.

screen

The malware features a modular architecture: the main backdoor component is supplemented with an encrypted configuration file and rootkit drivers. These drivers enable the malicious application to hide its presence. All Trojan versions use the same configuration file containing the modules' settings.

screen

BackDoor.DaVinci.1 allows criminals to gain full control over an infected computer. In addition, the Trojan saves and transmits information about the infected machine to criminals, acts as a key logger, can take screenshots, and intercept e-mail, ICQ, Skype messages and data captured by a microphone or video camera connected to a computer. In addition, the backdoor has a large set of tools to bypass anti-virus software and firewalls, so it may run unnoticed in a system for a long time. Interestingly, BackDoor.DaVinci.1 for Mac OS X is the first instance of malware for the platform that uses rootkit technologies to hide its files and processes.

HackingTeam criminals call their brainchild a 21st-century weapon and sell BackDoor.DaVinci.1 as a remote control and espionage solution. The Trojan poses a serious threat to users, because it not only intercepts any information on the infected computer but also gives criminals full control over a compromised system, so that they can render it non-operational, for example, by damaging or removing its components.

Despite BackDoor.DaVinci.1 developers' claims that this malicious application can withstand any modern anti-virus program, Dr.Web for Windows and Dr.Web for Mac OS X detect and successfully remove BackDoor.DaVinci.1; therefore, Dr.Web users are well protected against this threat.

Back to news
Company | News&Events | Send a virus | Online scanner | Privacy policy | Site map
[Google+] [Blog Dr.Web] [You Tube] [Twitter] [Facebook]
Dr.Web
© Doctor Web
2003 — 2013
Doctor Web is the Russian developer of Dr.Web anti-virus software. We have been developing our products since 1992. The company is a key player on the Russian market for software that meets the fundamental need of any business — information security. Doctor Web is one of the few anti-virus vendors in the world to have its own technologies to detect and cure malware. Our anti-virus protection system allows the information systems of our customers to be protected from any threats, even those still unknown. Doctor Web was the first company to offer an anti-virus as a service and, to this day, is still the undisputed Russian market leader in Internet security services for service providers. Doctor Web has received state certificates and awards; our satisfied customers spanning the globe are clear evidence of the high quality of the products created by our talented Russian programmers.


Rambler 100